
OpenAI incident exposes patched Linux IPv6 flaw and urgent patch steps
A patched Linux kernel vulnerability, CVE-2026-53362 (IPv6 Frag Gap), played a role in OpenAI’s Hugging Face incident, showing how a local foothold can escalate to root via an IPv6 UDP path; patches exist in recent kernels but many systems remain unpatched. Security guidance: apply vendor kernel updates, reboot to load the new kernel, prioritize patching for high-risk workloads, verify container-host boundaries, and consider temporary mitigations (e.g., disabling IPv6) if needed. Monitor for signs of compromise and expect more AI-enabled exploits as attackers leverage kernel bugs to gain control.